Privacy Policy

Privacy Policy

Section 01

Information we collect

We collect personal data that you provide directly to us — including your name, email address, telephone number, job title, employer, and country of residence — when you submit an enquiry through our contact form, request a consultation, or onboard as an institutional counterparty. We also collect technical data automatically when you visit our website (IP address, browser type, pages visited, referrer) through standard server logs.

For institutional clients, we additionally collect corporate identification documents (trade licence, beneficial ownership declaration, KYC pack) as required by UAE Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and the DMCC AML Rulebook.

Section 02

How we use it

Personal data is used for: (a) responding to enquiries and onboarding requests; (b) performing KYC, sanctions screening, and source-of-funds verification required by UAE AML law; (c) operating our refinery, minting, certification, and QR-tracking services; (d) meeting record-keeping obligations under DMCC and UAE Central Bank regulations; (e) sending operational notifications (shipment status, certificate delivery, compliance updates) that are part of our service delivery, not marketing.

We do not sell, rent, or trade personal data with third parties for marketing purposes.

Section 03

Cookies

Our public website uses a minimal set of first-party cookies: a session cookie that maintains your login state across the dashboard, and an analytics cookie that records anonymised, aggregate page-view counts. We do not use third-party advertising cookies. The dashboard additionally uses a JWT stored in localStorage for session continuity — this can be cleared from your browser at any time.

Section 04

Third-party services

We share personal data only with: (a) our hosting and infrastructure providers (UAE-based and EU-based, ISO 27001 certified); (b) our XRF and assay equipment vendors, solely for instrument calibration and firmware updates; (c) our QR-generation service, which receives no personal data — only the bar serial number; (d) UAE government authorities where required by law (DMCC, Ministry of Economy, relevant free-zone regulator). All third parties are bound by written data-processing agreements.

Section 05

Data retention

Client onboarding records are retained for a minimum of seven (7) years from the end of the engagement, in line with UAE Federal Decree-Law No. 20 of 2018 and the DMCC AML Rulebook. Transaction records (minted bar serials, certificates, QR scan logs) are retained for the lifetime of the bar plus seven years. Marketing enquiry data is retained for twenty-four (24) months unless a longer relationship is established.

Section 06

Your rights under UAE PDPL

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and its implementing regulations, you have the right to: (a) access the personal data we hold about you; (b) request correction of inaccurate data; (c) request deletion of data that is no longer required for the original purpose, subject to legal retention obligations; (d) withdraw consent where processing is based on consent; (e) lodge a complaint with the UAE Data Office.

To exercise any of these rights, write to [email protected]. We respond within thirty (30) calendar days.

Contact

Data Protection Officer
Welfinz Refinery DMCC
DMCC Business Centre, JLT, Dubai, UAE
[email protected]